krasnika^

РЕШЕН
Съмнение за инфектирана система

    18 мнения в тази тема


    Здравейте, бихте ли ми казали дали имам повод за притеснение. Клавиатурата ми и мишката отказват на моменти, което ме навежда на мисълта че е заразена машината. Работи бавно и ми дава на моменти син екран. Прилагам логовете:

    DDS:

     

    DDS (Ver_2011-09-30.01) - NTFS_x86 
    Internet Explorer: 8.0.6001.18702
    Run by MONI at 14:35:59 on 2013-05-11
    Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.894.97 [GMT 3:00]
    .
    AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
    .
    ============== Running Processes ================
    .
    C:WINDOWSExplorer.EXE
    C:WINDOWSsystem32spoolsv.exe
    C:Program FilesAviraAntiVir Desktopsched.exe
    C:Program FilesAviraAntiVir Desktopavguard.exe
    C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
    C:WINDOWSSystem32PAStiSvc.exe
    C:Program FilesTeamViewerVersion8TeamViewer_Service.exe
    C:Program FilesVIAVIAudioiHDADeckHDeck.exe
    C:Program FilesAviraAntiVir Desktopavgnt.exe
    C:Program FilesSkypePhoneSkype.exe
    C:WINDOWSsystem32ctfmon.exe
    C:Program FilesTeamViewerVersion8TeamViewer.exe
    C:Program FilesAviraAntiVir Desktopavshadow.exe
    C:Program FilesTeamViewerVersion8tv_w32.exe
    C:WINDOWSSystem32alg.exe
    C:Program FilesGoogleChromeApplicationchrome.exe
    C:Program FilesGoogleChromeApplicationchrome.exe
    C:Program FilesGoogleChromeApplicationchrome.exe
    C:Program FilesMozilla Firefoxfirefox.exe
    c:program filesteamviewerversion8TeamViewer_Desktop.exe
    C:Program FilesGoogleChromeApplicationchrome.exe
    C:WINDOWSsystem32wbemwmiprvse.exe
    C:WINDOWSsystem32svchost.exe -k DcomLaunch
    C:WINDOWSsystem32svchost.exe -k rpcss
    C:WINDOWSSystem32svchost.exe -k netsvcs
    C:WINDOWSsystem32svchost.exe -k NetworkService
    C:WINDOWSsystem32svchost.exe -k LocalService
    C:WINDOWSsystem32svchost.exe -k LocalService
    C:WINDOWSsystem32svchost.exe -k imgsvc
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www1.delta-search.com/?affID=119529&babsrc=HP_ss&mntrId=5C83002268826863
    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll
    uRun: [skype] "c:program filesskypephoneSkype.exe" /minimized /regrun
    uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe
    mRun: [HDAudDeck] c:program filesviaviaudioihdadeckHDeck.exe 1
    mRun: [avgnt] "c:program filesaviraantivir desktopavgnt.exe" /min
    dRun: [CTFMON.EXE] c:windowssystem32CTFMON.EXE
    uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    uPolicies-Explorer: NoDriveAutoRun = dword:67108863
    uPolicies-Explorer: NoDrives = dword:0
    mPolicies-Explorer: NoDriveAutoRun = dword:67108863
    mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
    mPolicies-Explorer: NoDrives = dword:0
    mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
    mPolicies-Explorer: NoDriveAutoRun = dword:67108863
    IE: E&xport to Microsoft Excel - c:progra~1micros~2office11EXCEL.EXE/3000
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe
    TCP: NameServer = 89.215.233.2 89.215.246.40
    TCP: Interfaces{A48477B5-DFB6-4E66-93CA-3491DD09FD48} : DHCPNameServer = 89.215.233.2 89.215.246.40
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:program filescommon filesskypeSkype4COM.dll
    SecurityProviders: SecurityProviders = msapsspc.dll, schannel.dll, credssp.dll, digest.dll, msnsspc.dll
    LSA: Security Packages =  kerberos msv1_0 schannel wdigest tspkg
    mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:program filesgooglechromeapplication26.0.1410.64installerchrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:documents and settingsmoniapplication datamozillafirefoxprofiles5w3wuf8l.default
    FF - plugin: c:documents and settingsall usersapplication datanexoneungmnpNxGameeu.dll
    FF - plugin: c:program filesadobereader 9.0readerairnppdf32.dll
    FF - plugin: c:program filesgoogleupdate1.3.21.145npGoogleUpdate3.dll
    FF - plugin: c:windowssystem32macromedflashNPSWF32_11_5_502_135.dll
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: extensions.tuvaro.hpOld0 - 
    FF - user.js: extensions.tuvaro.tlbrSrchUrl - hxxp://tuvaro.com/ws/?source=9e9471a2&tbp=main&toolbarid=base&u=5c8395d3000000000000002268826863&q=
    FF - user.js: extensions.tuvaro.id - 5c8395d3000000000000002268826863
    FF - user.js: extensions.tuvaro.appId - {2768469C-717B-401F-8532-C6D88BAE0339}
    FF - user.js: extensions.tuvaro.instlDay - 15812
    FF - user.js: extensions.tuvaro.vrsn - 1.8.17.1
    FF - user.js: extensions.tuvaro.vrsni - 1.8.17.1
    FF - user.js: extensions.tuvaro.vrsnTs - 1.8.17.114:03:46
    FF - user.js: extensions.tuvaro.prtnrId - tuvaro
    FF - user.js: extensions.tuvaro.prdct - tuvaro
    FF - user.js: extensions.tuvaro.aflt - orgnl
    FF - user.js: extensions.tuvaro.smplGrp - none
    FF - user.js: extensions.tuvaro.tlbrId - base
    FF - user.js: extensions.tuvaro.instlRef - 9e9471a2
    FF - user.js: extensions.tuvaro.dfltLng - 
    FF - user.js: extensions.tuvaro.excTlbr - false
    FF - user.js: extensions.tuvaro.ffxUnstlRst - false
    FF - user.js: extensions.tuvaro.admin - false
    FF - user.js: extensions.tuvaro.cam - 
    FF - user.js: extensions.tuvaro.autoRvrt - false
    FF - user.js: extensions.tuvaro.rvrt - false
    FF - user.js: extensions.tuvaro.hmpg - true
    FF - user.js: extensions.tuvaro.hmpgUrl - hxxp://tuvaro.com/ws/?source=9e9471a2&tbp=homepage&toolbarid=base&u=5c8395d3000000000000002268826863
    FF - user.js: extensions.tuvaro.dfltSrch - true
    FF - user.js: extensions.tuvaro.srchPrvdr - Tuvaro
    FF - user.js: extensions.tuvaro.kw_url - hxxp://tuvaro.com/ws/?source=9e9471a2&tbp=url&toolbarid=base&u=5c8395d3000000000000002268826863&q=
    FF - user.js: extensions.tuvaro.dnsErr - true
    FF - user.js: extensions.tuvaro.newTab - true
    FF - user.js: extensions.tuvaro.newTabUrl - chrome://tuvaro/content/new browser tab.html?source=9e9471a2&tbp=tab&u=5c8395d3000000000000002268826863
    FF - user.js: extensions.delta.tlbrSrchUrl - 
    FF - user.js: extensions.delta.id - 5c8395d3000000000000002268826863
    FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
    FF - user.js: extensions.delta.instlDay - 15812
    FF - user.js: extensions.delta.vrsn - 1.8.16.16
    FF - user.js: extensions.delta.vrsni - 1.8.16.16
    FF - user.js: extensions.delta.vrsnTs - 1.8.16.1614:06:01
    FF - user.js: extensions.delta.prtnrId - delta
    FF - user.js: extensions.delta.prdct - delta
    FF - user.js: extensions.delta.aflt - babsst
    FF - user.js: extensions.delta.smplGrp - none
    FF - user.js: extensions.delta.tlbrId - base
    FF - user.js: extensions.delta.instlRef - sst
    FF - user.js: extensions.delta.dfltLng - en
    FF - user.js: extensions.delta.excTlbr - false
    FF - user.js: extensions.delta.ffxUnstlRst - true
    FF - user.js: extensions.delta.admin - false
    FF - user.js: extensions.delta.autoRvrt - false
    FF - user.js: extensions.delta.rvrt - false
    FF - user.js: extensions.delta.newTab - false
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 mv61xxmm;mv61xxmm;c:windowssystem32driversmv61xxmm.sys [2012-7-12 13616]
    R0 mv64xxmm;mv64xxmm;c:windowssystem32driversmv64xxmm.sys [2012-7-12 5632]
    R0 mvxxmm;mvxxmm;c:windowssystem32driversmvxxmm.sys [2012-7-12 13616]
    R0 nvlegacy;nvlegacy;c:windowssystem32driversnvlegacy.sys [2012-7-12 100736]
    R1 avkmgr;avkmgr;c:windowssystem32driversavkmgr.sys [2013-1-6 37352]
    R2 AntiVirSchedulerService;Avira Scheduler;c:program filesaviraantivir desktopsched.exe [2013-1-6 86752]
    R2 AntiVirService;Avira Real-Time Protection;c:program filesaviraantivir desktopavguard.exe [2013-1-6 110816]
    R2 avgntflt;avgntflt;c:windowssystem32driversavgntflt.sys [2013-1-6 84744]
    R2 TeamViewer8;TeamViewer 8;c:program filesteamviewerversion8TeamViewer_Service.exe [2013-3-5 3574624]
    R3 MonitorFunction;Driver for Monitor;c:windowssystem32driversTVMonitor.sys [2013-2-3 13304]
    R3 PAC207;SoC PC-Camer@;c:windowssystem32driverspfc027.sys [2005-2-24 162176]
    R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:windowssystem32driversviahduaa.sys [2012-12-8 279680]
    S2 gupdate;Услуга на Google Актуализация (gupdate);c:program filesgoogleupdateGoogleUpdate.exe [2013-1-12 116648]
    S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:program filesgoogleupdateGoogleUpdate.exe [2013-1-12 116648]
    S3 vtany;vtany;??c:windowsvtany.sys --> c:windowsvtany.sys [?]
    S3 xhunter1;xhunter1;??c:windowsxhunter1.sys --> c:windowsxhunter1.sys [?]
    S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:windowssystem32macromedflashFlashPlayerUpdateService.exe [2012-7-12 250808]
    S4 SkypeUpdate;Skype Updater;c:program filesskypeupdaterUpdater.exe [2013-2-28 161384]
    .
    =============== Created Last 30 ================
    .
    2013-04-18 13:37:10 -------- d-----w- c:documents and settingsall usersapplication dataInterAction studios
    2013-04-17 15:58:18 -------- d-----w- c:windowssystem32appmgmt
    2013-04-17 11:05:32 -------- d-----w- c:documents and settingsmoniapplication dataBabylon
    2013-04-17 11:05:32 -------- d-----w- c:documents and settingsall usersapplication dataBabylon
    2013-04-17 11:03:19 -------- d--h--w- c:windowssystem32GroupPolicy
    2013-04-14 00:02:47 1072544 ----a-w- c:windowssystem32nvdrsdb1.bin
    2013-04-14 00:02:47 1072544 ----a-w- c:windowssystem32nvdrsdb0.bin
    2013-04-14 00:02:47 1 ----a-w- c:windowssystem32nvdrssel.bin
    2013-04-14 00:02:08 -------- d-----w- c:program filesNVIDIA Corporation
    2013-04-11 19:20:18 26520 ----a-w- c:program filesmozilla firefoxplugin-hang-ui.exe
    2013-04-11 19:20:01 96664 ----a-w- c:program filesmozilla firefoxwebapprt-stub.exe
    2013-04-11 19:20:01 19352 ----a-w- c:program filesmozilla firefoxxpcom.dll
    2013-04-11 19:20:01 18581400 ----a-w- c:program filesmozilla firefoxxul.dll
    2013-04-11 19:20:00 92056 ----a-w- c:program filesmozilla firefoxsmime3.dll
    2013-04-11 19:20:00 867000 ----a-w- c:program filesmozilla firefoxuninstallhelper.exe
    2013-04-11 19:20:00 272280 ----a-w- c:program filesmozilla firefoxupdater.exe
    2013-04-11 19:20:00 170232 ----a-w- c:program filesmozilla firefoxwebapp-uninstaller.exe
    2013-04-11 19:20:00 157080 ----a-w- c:program filesmozilla firefoxssl3.dll
    2013-04-11 19:20:00 152472 ----a-w- c:program filesmozilla firefoxsoftokn3.dll
    .
    ==================== Find3M  ====================
    .
    2013-03-27 15:22:35 84744 ----a-w- c:windowssystem32driversavgntflt.sys
    2013-03-27 15:22:35 37352 ----a-w- c:windowssystem32driversavkmgr.sys
    2013-03-08 08:35:47 293376 ----a-w- c:windowssystem32winsrv.dll
    2013-03-07 03:23:36 2070016 ----a-w- c:windowssystem32ntkrnlpa.exe
    2013-03-07 01:31:48 2193536 ----a-w- c:windowssystem32ntoskrnl.exe
    2013-03-02 02:05:19 920064 ----a-w- c:windowssystem32wininet.dll
    2013-03-02 02:05:18 43520 ----a-w- c:windowssystem32licmgr10.dll
    2013-03-02 02:05:18 1469440 ----a-w- c:windowssystem32inetcpl.cpl
    2013-03-02 01:31:30 1876224 ----a-w- c:windowssystem32win32k.sys
    2013-03-02 01:08:57 385024 ----a-w- c:windowssystem32html.iec
    2013-02-12 00:32:23 12928 ----a-w- c:windowssystem32driversusb8023.sys
    .
    ============= FINISH: 14:37:09,76 ===============
     
    Attach:
     
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-09-30.01)
    .
    Microsoft Windows XP Professional
    Boot Device: DeviceHarddiskVolume1
    Install Date: 07.5.2005 г. 18:24:05
    System Uptime: 11.5.2013 г. 12:55:05 (2 hours ago)
    .
    Motherboard: FOXCONN |  | M61PMV
    Processor: AMD Sempron Processor LE-1200 | AMD Sempron Processor LE-1200 | 2109/201mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 68 GiB total, 59,224 GiB free.
    D: is FIXED (NTFS) - 165 GiB total, 146,672 GiB free.
    E: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    No restore point in system.
    .
    ==== Installed Programs ======================
    .
    µTorrent
    Пакет за езиков интерфейс на Windows
    Adobe Flash Player 11 ActiveX
    Adobe Flash Player 11 Plugin
    Adobe Reader 9.5.0 - Bulgarian
    Avira Free Antivirus
    CCleaner
    Chicken Invaders 3 Free Trial
    Compatibility Pack for the 2007 Office system
    Dekaron
    Diner Dash - Hometown Hero
    Google Chrome
    Google Update Helper
    K-Lite Codec Pack 8.4.0 (Standard)
    Microsoft Office 2003 Bulgarian User Interface Pack
    Microsoft Office File Validation Add-In
    Microsoft Office Professional Edition 2003
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
    Mozilla Firefox 20.0.1 (x86 bg)
    MSXML 4.0 SP3 Parser (KB2758694)
    Nero 7 Micro
    NVIDIA Drivers
    OnScreenKeys 5.0.48
    PC Camer@
    Platform
    REALTEK GbE & FE Ethernet PCI NIC Driver
    Realtek High Definition Audio Driver
    Security Update for Windows Internet Explorer 8 (KB2744842)
    Security Update for Windows Internet Explorer 8 (KB2761465)
    Security Update for Windows Internet Explorer 8 (KB2792100)
    Security Update for Windows Internet Explorer 8 (KB2797052)
    Security Update for Windows Internet Explorer 8 (KB2799329)
    Security Update for Windows Internet Explorer 8 (KB2809289)
    Security Update for Windows Internet Explorer 8 (KB2817183)
    Security Update for Windows XP (KB2808735)
    Security Update for Windows XP (KB2813170)
    Security Update for Windows XP (KB2820917)
    Skype™ 6.3
    TeamViewer 8
    The KMPlayer (remove only)
    VIA п»ї
    WebFldrs XP
    Winamp
    WinRAR 4.01 (32-битова версия)
    .
    ==== Event Viewer Messages From Past Week ========
    .
    07.5.2013 г. 13:16:53, error: Service Control Manager [7031]  - The Avira Real-Time Protection service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.
    07.5.2013 г. 13:16:53, error: Service Control Manager [7006]  - The ScRegSetValueExW call failed for FailureActions with the following error:  Access is denied.
    07.5.2013 г. 13:16:53, error: Service Control Manager [7006]  - The ScRegSetValueExW call failed for FailureActions with the following error:  Access is denied.
    .
    ==== End Of File ===========================
     

    Благодаря  :)

     

    1 човек харесва това

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Здравейте,

     

    Извинете за забавянето.

    Може ли да архивирате файловете от папката C:Windowsminidump и да ги качите на хост по-избор.

    Публикувайте линк за download в следващия си пост.

     

    Поздрави!

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Здравейте,

     

    Извинете за забавянето.

    Може ли да архивирате файловете от папката C:Windowsminidump и да ги качите на хост по-избор.

    Публикувайте линк за download в следващия си пост.

     

    Поздрави!

    Привет, ето линк към архива: http://dox.bg/files/dw?a=7813a0da6a

    1 човек харесва това

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Здравейте,

     

     

    Прегледах дъмп файловете и всички се дължат на драйвъра на VIA за звука:

     

    Probably caused by : viahduaa.sys ( viahduaa+19e60 )

     

    Нека да видим каква е вашаха хардуерна конфигурация за да обновим драйвъра до последната му версия.

     

    Свалете програмата Публикувано изображениеHWiNFO32

    След успешна инсталация и стартиране, ще се появи следния прозорец:
    Публикувано изображение

    Натиснете Run.

    Изчакайте търпеливо. След това изберете Save Report и HTML формат и натиснете Browse.

    Посочете вашия десктоп и натиснете Next.

    Ще се появява се Report Filter, изберете Finish.

    Публикувано изображение

    На десктопа ще се появи HTML файл с име "User Name", където "User Name" е името на компютъра Ви (например файла от снимката се казва HOLLER-PC.HTM). Качете файла тук и публикувайте линка за download в следващия си пост.


    И един от дъмповете се дължи на следното:

     

    Probably caused by : memory_corruption

     

    За тестване на РАМ паметта може да опитате с Memtest86+ 4.20
    Разархивирайте архива и запишете ISO файла с Burnaware например за да се получи буутващ диск с опцията Burn Image

    Публикувано изображение
    След това направете от БИОС-а CD/DVD устройството да е първото стартиращо устройство и направете проверка на РАМ паметта.
    Ако теста е успешен не би трябвало да има грешки:

    Публикувано изображение

    За да сте напълно сигурни, че РАМ-а е ок е добре да оставите теста за през нощта за поне едно 8-10 часа и още по-добре извадете всички плочки и оставете само една и ги тествайте една по една.
    Ако бъдат открити грешки ще видите грешки в червен фон подобно на тези:
    Публикувано изображение

    3 души харесват това

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Ето линка от стъпка 1: http://file.bg/c233164FmVLa


    1 човек харесва това

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Здравейте,

     

    Чудя се дали направо не можете да си карате само на драйвъра на Реалтек за звука, защото имате два драйвъра:

     

    Realtek HDA Audio Drive
    VIA HDA Audio Drive

     

    На сайта на Foxconn драйвърите са доста стари - от 2009-та

     

    На сайта на VIA намерий два за вашия кодек: VIA VT1708B CE

     

    По-стара, но сертифицирана версия - 10.005D Dated: 25-Jul-2012

     

     

    и  по-нова версия (не сертифицирана, но едва ли ще е проблем) - 10.1200A Dated: 7-Nov-2012

     

    Пробвайте и двата и вижте дали сините екрани ще изчезнат. При възможност обновете и останалите драйвъри (но за предпочитане е да не използвате допълнителен софтуер, защото те често свалят погрешните драйвъри за дадена конфигфурация).

     

    Все пак тествайте и РАМ-а и после пишете как е положението.

     

    Също така да почистим и малко Adware и да проверим за активни гадинки:

     

     

     

    СТЪПКА 1

     

     

    Публикувано изображение Изтеглете и стартирайте програмата AdwCleaner (by Xplode).

    • [*]Затворете всички стартирани програми и браузъри [*]Кликнете два пъти върху
    adwcleaner.exe за да стартирате инструмента. [*]Този път маркирайте Delete [*]Вашият компютър ще се рестартира автоматично. Текстовия файл ще се отвори след рестарта. [*]Моля, да публикувате съдържанието на този лог в отговора си [*]Можете да намерите лога,който автоматично се запомня тук C:AdwCleaner[s1].txt.

     

     

     

    СТЪПКА 2

     

     

     

    Публикувано изображение Моля изтеглете Junkware Removal Tool на вашия десктоп.


    • [*]Спрете временно работата на защитните програми. [*]Стартирайте инструмента
    JRT.exe [*]Ще се отвори ДОС прозорец. Натиснете което и да е копче от клавиатурата. [*]Затворете излишните приложения и всички браузъри и изчакайте проверката да завърши. [*]Ще се появи лог файл (който можете да намерите и ръчно на десктопа с името JRT.txt). [*]Моля копирайте съдържанието на лог файла в следващия си пост.

     

     

     

    СТЪПКА 3

     

     

    Публикувано изображение Изтеглете Malwarebytes' Anti-Malware

     

    • [*]Кликнете два пъти върху
    mbam-setup.exe, за да инсталирате програмата. [*]Уверете се, че са поставени отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware. След това кликнете на Finish. [*]Ако има намерени обновявания, тя ще ги изтегли и инсталира. [*]Стартирайте програмата и изберете "Perform Quick Scan", след това кликнете на Scan. [*]Сканирането ще отнеме малко време, затова моля да бъдете търпеливи. [*]Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата. [*]Уверете се, че на всички редове има отметки, и кликнете на Remove Selected. [*]Когато всичко бъде премахнато, в Notepad ще бъде отворен лог. [*]Прикачете този лог в следващия си коментар в темата.

    Забележка: Ако MalwareBytes'Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поискада рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

     

     

    СТЪПКА 4

     

     

    Публикувано изображение
    1) Изтеглете: ESET Online Scanner
    2) Стартирайте esetsmartinstaller_enu.exe
    3) Сложете отметка на YES, I accept the Terms of Use и изберете Start
    4) Скенерът ще започне да изтегля компонентите, които са му необходими.
    5) Уверете се, че има отметки на следните редове, включително и тези от менюто Advanced Settings:

    • [*]
    Scan archives [*]Scan for potentially unwanted applications [*]Scan for potentially unsafe applications [*]Enable Anti-Stealth technology

    Уверете се че, Remove found threats няма отметка!

    И накрая изберете Start

    6) Скенерът ще започне да изтегля последните дефиниции.
    7) След, като сканирането завърши изберете Finish.
    8) Отидете в: C:Program FilesESETESET Online Scanner.

    9) Прикачете лог с името log.txt файла в следващия си пост.

     

     

     

    СТЪПКА 5

     

     

     

    Публикувано изображение
    Изтеглете Security Check от screen317 от този линк или и го запаметете на вашия десктоп.

    • [*]Кликнете два пъти върху
    SecurityCheck.exe и следвайте инструкциите. [*]Накрая, автоматично ще се отвори текстов документ, наречен checkup.txt, моля прикачете го в следващия ви коментар в тази тема.

    2 души харесват това

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    публикувано (редактирано)

    Здравейте, ето резултати: 

     

     

    П.С. Снимката е прекалено голяма за да я кача тук, затова ви пускам линк:  

    http://dox.bg/files/dw?a=a70a18da55

     

    AdwCleanerS2.txt

    checkup.txt

    JRT.txt

    log.txt

    Редактирано от krasnika^ (преглед на промените)
    1 човек харесва това

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Липсва лога от MBAM и за съжаление снимката от Eset не върши работа, защото файловете са с криптирани имена, но щом не пазите лога (както ми писахте по Л.С.) нищо не можем да направим за да видим какво е изтрила програмата след първото стартиране. Втория лог от Есет е чист.

     

    Как е сега положението - обновихте ли драйвърите за звука и продължават ли проблемите заради които отворихте темата?

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    публикувано (редактирано)

    Прикачам липсващия лог. Появи се нов проблем с драйверите на звука - след инсталацията на новия драйвер ( без сертификата) не ми позволява да включа микрофона в предния панел. Машината се държи по - добре. Само да попитам: да махам ли инструментите които ползвахме ? И какво да правя с файловете под карантина ? Благодаря ви.

    mbam-log-2013-04-06 (11-36-38).txt

    Редактирано от krasnika^ (преглед на промените)
    1 човек харесва това

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Здравейте, файловете на Eset Online Scaner-a и папката в която са инсталирани остана след указаната от вас деинсталация както и карантината на програмата. Компютъра е много "по - пъргав" ако мога така да се изразя. Справихме се успешно с драйверите, и вече всичко е наред. Засега няма сини екрани и едва ли ще има повече проблеми след вашата намеса, за което ви Благодаря :wors: . Проблемите са решени. Само ми укажете начин по който да премахна програмата Eset Online Scaner  безопасно. Поздрави и лека работа :)

    1 човек харесва това

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    публикувано (редактирано)

    Явно прибързах със заключенията относно сините екрани. Днес пак се появи ето кода на грешката: 0x000000D1(0xEB0F6E60,0x00000002,0x00000008,0xEB0F6E60). Бихте ли ми казали от какво може да е ? При рестарт на системата и опит да се затвори доклада за грешка на Microsoft дава пак синя страница с този код:0x000000d1(0xEB161E60,0x00000002,0x00000000,0xEB161E60).

    Редактирано от krasnika^ (преглед на промените)
    1 човек харесва това

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Най-вероятно причината е в драйвър - и може би отново този на VIA.

     

     

    DRIVER_IRQL_NOT_LESS_OR_EQUAL

     

     

     

    Вижте дали има нов dmp файл в папката C:Windowsminidump и ако има го архивирайте.

     

    Ако отново се окаже, че е заради драйвъра на VIA инсталирайте последната версия без сертификата и пробвайте да работите без микрофона или пробвайте изцяло да карате само на драйвърите на Realtek. Щом помагате по TeamViewer-a няма и как да тествате рама от разстояние - но като имате физически достъп до компютъра тествайте плочките на РАМ-а една по една с Memtest, както бях написал по-нагоре.

     

    Също така:

     

    Изтеглете Autoruns и:

     

    • [*]Стартирайте програмата; [*]Изберете
    Options => Filter Options => сложете отметки пред Verify Code Signature и Hide Microsoft Entries; [*]От менюто File -> Refresh; [*]От менюто File -> Save...; [*]Запазете файла някъде с желано от вас име (във формат arn), архивирайте го с програма по желание и го прикачете към темата.

    ПС: Остатъците от Есет можете да изтриете и ръчно.

    1 човек харесва това

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Сложихме драйвера на производителя ( с който е купено дъното) и за сега има звук. Има нови Дъмп файлове които прилагам към темата, както и резултата от програмата който поискахте. Поздрави :) http://dox.bg/files/dw?a=b5f4cf62a5 - Minidump

    http://dox.bg/files/dw?a=46a1d5d226 Autoruns - резултат

     

     

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Лошото е, че драйвъра от сайта на производителя, който съм дал е доста стар и може би дори вие в момента сте били със същата версия, която е правила и проблема.

    Според дъмп файловете отново виновен е драйвъра на VIA - viahduaa.sys.

     

    Вариантите са 2.

     

    1. Деинсталирате го и използвате само този на Realtek.

    2. Инсталирате сертифицираната версия, която е по-нова версия от тази на сайта на Foxconn, но и по-стара от несертифицираната версия от сайта на Via.

     

    Поне знаете, къде е проблема! :)

     

    Колкото до Autoruns можете да премахнете следните отметки (не да ги изтриете, а само ги отмаркирайте):

     

    Adobe ARM

    HDAudDeck

     

    И после затворете програмата.

    Изтрийте използваните от нас инструменти. Аз маркирам случая като решен...просто за драйвъра за VIA ако това не помогне не се сещам за друго адекватно решение...

     

    Поздрави!

    1 човек харесва това

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Здравейте,

     

     

    Прегледах дъмп файловете и всички се дължат на драйвъра на VIA за звука:

     

     

    Нека да видим каква е вашаха хардуерна конфигурация за да обновим драйвъра до последната му версия.

     

    Свалете програмата Публикувано изображениеHWiNFO32

    След успешна инсталация и стартиране, ще се появи следния прозорец:

    Публикувано изображение

    Натиснете Run.

    Изчакайте търпеливо. След това изберете Save Report и HTML формат и натиснете Browse.

    Посочете вашия десктоп и натиснете Next.

    Ще се появява се Report Filter, изберете Finish.

    Публикувано изображение

    На десктопа ще се появи HTML файл с име "User Name", където "User Name" е името на компютъра Ви (например файла от снимката се казва HOLLER-PC.HTM). Качете файла тук и публикувайте линка за download в следващия си пост.

    И един от дъмповете се дължи на следното:

     

     

    За тестване на РАМ паметта може да опитате с Memtest86+ 4.20

    Разархивирайте архива и запишете ISO файла с Burnaware например за да се получи буутващ диск с опцията Burn Image

    Публикувано изображение

    След това направете от БИОС-а CD/DVD устройството да е първото стартиращо устройство и направете проверка на РАМ паметта.

    Ако теста е успешен не би трябвало да има грешки:

    Публикувано изображение

    За да сте напълно сигурни, че РАМ-а е ок е добре да оставите теста за през нощта за поне едно 8-10 часа и още по-добре извадете всички плочки и оставете само една и ги тествайте една по една.

    Ако бъдат открити грешки ще видите грешки в червен фон подобно на тези:

    Публикувано изображение

    С огромно закъснение, за което много се извинявам, бих искал да ви съобщя, че състоянието на системата е много добро. Наложи се да преинсталираме целия компютъра с пълно форматиране и разцепване на харддиска, след което направих теста на РАМ паметта ( както ме посъветвахте - цяла нощ ) резултата е че : няма грешки в паметта, и за момента работи добре, и без сини екрани :)  Още веднъж Благодаря за помощта и положените усилия :)

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Все пак причината бе и си остава в драйвърите на Realtek...и затова го имайте предвид! :)

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    :)  точно затова този път съм качил всички без тях :)

    1 човек харесва това

    Сподели този отговор


    Линк към този отговор
    Сподели в други сайтове

    Регистрирайте се или влезете в профила си за да коментирате

    Трябва да имате регистрация за да може да коментирате това

    Регистрирайте се

    Създайте нова регистрация в нашия форум. Лесно е!


    Нова регистрация

    Вход

    Имате регистрация? Влезте от тук.


    Вход

    • Подобни теми

      • от Атанас Славов
        Здравейте! Направих сканиране с Microsot Security Essentials и откри някакви 2 зарази. Мисля, че може да има все още останало нещо. Понякога работи доста бавно системата и също така имам трудност с chrome браузъра, не мога да задам google търсачка, а само някаква wepageing. Не мога да изтрия от контрол панела McAfee, остава на това бяло прозорче, след като натисна uninstall и до там....  Имам проблем с прикачването на файл, за това Addition файла го качвам в dox.bg:
        Addition.txt - http://dox.bg/files/dw?a=76248cba29
        Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-05-2017
        Ran by Vesi (administrator) on VESI-PC (16-05-2017 14:50:57)
        Running from C:\Users\Vesi\Desktop
        Loaded Profiles: Vesi (Available Profiles: Vesi)
        Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
        Internet Explorer Version 11 (Default browser: Chrome)
        Boot Mode: Normal
        Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
        ==================== Processes (Whitelisted) =================
        (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
        (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
        (Microsoft Corporation) C:\Windows\System32\wlanext.exe
        (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
        (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
        (TMRG,  Inc.) C:\Program Files (x86)\RelevantKnowledge\rlservice.exe
        (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
        (Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
        (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
        (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
        (Intel Corporation) C:\Windows\System32\igfxtray.exe
        (Intel Corporation) C:\Windows\System32\hkcmd.exe
        (Intel Corporation) C:\Windows\System32\igfxpers.exe
        (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
        (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
        (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.551\SSScheduler.exe
        (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
        (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
        (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
        (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
        (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
        (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
        (Microsoft Corporation) C:\Windows\System32\dllhost.exe
        (Microsoft Corporation) C:\Windows\System32\dllhost.exe
        ==================== Registry (Whitelisted) ====================
        (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
        HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [609144 2011-04-12] (Alps Electric Co., Ltd.)
        HKLM\...\Run: [QuickSet] => C:\Program Files\Dell\QuickSet\QuickSet.exe [3668336 2011-03-24] (Dell Inc.)
        HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1354712 2016-08-30] (Microsoft Corporation)
        HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
        Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
        HKU\S-1-5-21-1487217415-1589543797-577930275-1000\...\Run: [uTorrent] => C:\Program Files (x86)\uTorrent\uTorrent.exe [328056 2015-01-04] (BitTorrent, Inc.)
        HKU\S-1-5-21-1487217415-1589543797-577930275-1000\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
        HKU\S-1-5-21-1487217415-1589543797-577930275-1000\...\Run: [DellSystemDetect] => C:\Users\Vesi\AppData\Local\Apps\2.0\1O0V4VPR.HOC\AL1760X4.N4J\dell..tion_e30b47f5d4a30e9e_0005.000d_4ab2a66cfade09be\DellSystemDetect.exe [276776 2015-01-03] (Dell)
        Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk [2015-01-03]
        ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files (x86)\Digital Line Detect\DLG.exe (Avanquest Software )
        Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-05-02]
        ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.551\SSScheduler.exe (McAfee, Inc.)
        ==================== Internet (Whitelisted) ====================
        (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
        Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
        Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
        Tcpip\..\Interfaces\{DF408091-91BE-44AD-9492-1A51214C7FEE}: [DhcpNameServer] 192.168.0.1
        Internet Explorer:
        ==================
        HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
        HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
        HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
        HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
        HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
        HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
        HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
        HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
        HKU\S-1-5-21-1487217415-1589543797-577930275-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
        SearchScopes: HKU\S-1-5-21-1487217415-1589543797-577930275-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://istart.webssearches.com/web/?utm_source=b&utm_medium=kmp&utm_campaign=install_ie&utm_content=ds&from=kmp&uid=TOSHIBAXMK6475GSX_Z1CBT8W5TXXZ1CBT8W5T&ts=1422143907&type=default&q={searchTerms}
        SearchScopes: HKU\S-1-5-21-1487217415-1589543797-577930275-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://istart.webssearches.com/web/?utm_source=b&utm_medium=kmp&utm_campaign=install_ie&utm_content=ds&from=kmp&uid=TOSHIBAXMK6475GSX_Z1CBT8W5TXXZ1CBT8W5T&ts=1422143907&type=default&q={searchTerms}
        SearchScopes: HKU\S-1-5-21-1487217415-1589543797-577930275-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://istart.webssearches.com/web/?utm_source=b&utm_medium=kmp&utm_campaign=install_ie&utm_content=ds&from=kmp&uid=TOSHIBAXMK6475GSX_Z1CBT8W5TXXZ1CBT8W5T&ts=1422143907&type=default&q={searchTerms}
        SearchScopes: HKU\S-1-5-21-1487217415-1589543797-577930275-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
        SearchScopes: HKU\S-1-5-21-1487217415-1589543797-577930275-1000 -> {94DA53C8-180E-4FF8-9C9C-04A75763891C} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=CPUID&o=14654&src=kw&q={searchTerms}&locale=en_EU&apn_ptnrs=^CV&apn_dtid=^YYYYYY^YY^BG&apn_uid=46C0F435-98E6-4D8A-B405-17A27A379AD7&apn_sauid=FA384896-5A5D-474A-B0FD-4671F19BB5BC
        SearchScopes: HKU\S-1-5-21-1487217415-1589543797-577930275-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://istart.webssearches.com/web/?utm_source=b&utm_medium=kmp&utm_campaign=install_ie&utm_content=ds&from=kmp&uid=TOSHIBAXMK6475GSX_Z1CBT8W5TXXZ1CBT8W5T&ts=1422143907&type=default&q={searchTerms}
        BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll [2009-01-26] (Safer Networking Limited)
        BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
        Toolbar: HKU\S-1-5-21-1487217415-1589543797-577930275-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
        StartMenuInternet: IEXPLORE.EXE - iexplore.exe
        FireFox:
        ========
        FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
        FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
        FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
        FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-02] (Google Inc.)
        FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-02] (Google Inc.)
        FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-28] (Adobe Systems Inc.)
        Chrome: 
        =======
        CHR DefaultProfile: Default
        CHR HomePage: Default -> hxxp://google.bg/
        CHR StartupUrls: Default -> "hxxps://www.google.bg/"
        CHR Profile: C:\Users\Vesi\AppData\Local\Google\Chrome\User Data\Default [2017-05-16]
        CHR Extension: (Google Презентации) - C:\Users\Vesi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-04]
        CHR Extension: (Google Документи) - C:\Users\Vesi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
        CHR Extension: (Google Диск) - C:\Users\Vesi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
        CHR Extension: (YouTube) - C:\Users\Vesi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-28]
        CHR Extension: (Google Търсене) - C:\Users\Vesi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-31]
        CHR Extension: (Електронни таблици от Google) - C:\Users\Vesi\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-04]
        CHR Extension: (Google Документи офлайн) - C:\Users\Vesi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
        CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\Vesi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
        CHR Extension: (Gmail) - C:\Users\Vesi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
        CHR Extension: (Chrome Media Router) - C:\Users\Vesi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-14]
        ==================== Services (Whitelisted) ====================
        (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
        S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.551\McCHSvc.exe [404376 2017-04-18] (McAfee, Inc.)
        R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [120888 2016-08-30] (Microsoft Corporation)
        S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-02-08] ()
        R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-08-30] (Microsoft Corporation)
        R2 RelevantKnowledge; C:\Program Files (x86)\RelevantKnowledge\rlservice.exe [186136 2013-08-17] (TMRG,  Inc.) <==== ATTENTION
        R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
        S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
        R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3386608 2013-02-08] (Intel® Corporation)
        ===================== Drivers (Whitelisted) ======================
        (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
        R2 cpuz133; C:\Windows\system32\drivers\cpuz133_x64.sys [20968 2010-05-11] (Windows (R) Win 7 DDK provider)
        R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
        R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
        S3 VGPU; System32\drivers\rdvgkmd.sys [X]
        ==================== NetSvcs (Whitelisted) ===================
        (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

        ==================== One Month Created files and folders ========
        (If an entry is included in the fixlist, the file/folder will be moved.)
        2017-05-16 14:50 - 2017-05-16 14:51 - 00012144 _____ C:\Users\Vesi\Desktop\FRST.txt
        2017-05-16 14:50 - 2017-05-16 14:50 - 00000000 ____D C:\FRST
        2017-05-16 14:48 - 2017-05-16 14:48 - 02429952 _____ (Farbar) C:\Users\Vesi\Desktop\FRST64.exe
        2017-05-16 14:09 - 2017-05-16 14:09 - 03480040 _____ (McAfee, Inc.) C:\Users\Vesi\Downloads\MCPR.exe
        2017-05-16 14:05 - 2017-05-16 14:05 - 22908888 _____ (Malwarebytes ) C:\Users\Vesi\Downloads\mbam-setup-2.2.0.1024.exe
        2017-05-16 13:56 - 2017-05-16 14:24 - 00000000 ____D C:\Windows\system32\appmgmt
        2017-05-16 11:13 - 2017-05-16 11:13 - 00391385 __RSH C:\VHIJQ
        2017-05-16 11:00 - 2017-05-16 13:48 - 00000000 ____D C:\Users\Vesi\Downloads\Windows Loader 2.1.7
        2017-05-16 10:57 - 2012-10-07 15:33 - 00001429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KJ_Starter.lnk
        2017-05-16 10:57 - 2012-10-06 01:07 - 00405881 _____ C:\Windows\KJ.exe
        2017-05-16 10:56 - 2017-05-16 10:57 - 00000000 ____D C:\Windows\KJ
        2017-05-16 09:53 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
        2017-05-16 09:53 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
        2017-05-16 09:53 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
        2017-05-16 09:53 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
        2017-05-16 09:53 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
        2017-05-16 09:53 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
        2017-05-16 09:53 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
        2017-05-16 09:53 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
        2017-05-16 09:53 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
        2017-05-16 09:53 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
        2017-05-16 09:53 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
        2017-05-16 09:53 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
        2017-05-16 09:53 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
        2017-05-16 09:53 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
        2017-05-16 09:53 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
        2017-05-16 09:53 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
        2017-05-16 09:53 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
        2017-05-16 09:53 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
        2017-05-16 09:53 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
        2017-05-16 09:53 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
        2017-05-16 09:53 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
        2017-05-16 09:53 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
        2017-05-16 09:53 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
        2017-05-16 09:53 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
        2017-05-16 09:53 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
        2017-05-16 09:53 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
        2017-05-16 09:53 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
        2017-05-16 09:53 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
        2017-05-16 09:53 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
        2017-05-16 09:53 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
        2017-05-16 09:53 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
        2017-05-16 09:53 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
        2017-05-16 09:53 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
        2017-05-16 09:53 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
        2017-05-16 09:53 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
        2017-05-16 09:53 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
        2017-05-16 09:53 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
        2017-05-16 09:53 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
        2017-05-16 09:53 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
        2017-05-16 09:53 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
        2017-05-16 09:53 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
        2017-05-16 09:53 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
        2017-05-16 09:53 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
        2017-05-16 09:53 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
        2017-05-16 09:53 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
        2017-05-16 09:53 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
        2017-05-16 09:53 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
        2017-05-16 09:53 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
        2017-05-16 09:53 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
        2017-05-16 09:53 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
        2017-05-16 09:53 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
        2017-05-16 09:53 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
        2017-05-16 09:53 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
        2017-05-16 09:53 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
        2017-05-16 09:53 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
        2017-05-16 09:53 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
        2017-05-16 09:53 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
        2017-05-16 09:53 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
        2017-05-16 09:53 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
        2017-05-16 09:53 - 2008-10-10 04:52 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
        2017-05-16 09:53 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
        2017-05-16 09:53 - 2008-10-10 04:52 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
        2017-05-16 09:53 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
        2017-05-16 09:53 - 2008-10-10 04:52 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
        2017-05-16 09:53 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
        2017-05-16 09:53 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
        2017-05-16 09:53 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
        2017-05-16 09:53 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
        2017-05-16 09:53 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
        2017-05-16 09:53 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
        2017-05-16 09:53 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
        2017-05-16 09:53 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
        2017-05-16 09:53 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
        2017-05-16 09:53 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
        2017-05-16 09:53 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
        2017-05-16 09:53 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
        2017-05-16 09:53 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
        2017-05-16 09:53 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
        2017-05-16 09:53 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
        2017-05-16 09:53 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
        2017-05-16 09:53 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
        2017-05-16 09:53 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
        2017-05-16 09:53 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
        2017-05-16 09:53 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
        2017-05-16 09:53 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
        2017-05-16 09:53 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
        2017-05-16 09:53 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
        2017-05-16 09:53 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
        2017-05-16 09:53 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
        2017-05-16 09:53 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
        2017-05-16 09:53 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
        2017-05-16 09:53 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
        2017-05-16 09:53 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
        2017-05-16 09:53 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
        2017-05-16 09:53 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
        2017-05-16 09:53 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
        2017-05-16 09:53 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
        2017-05-16 09:53 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
        2017-05-16 09:53 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
        2017-05-16 09:53 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
        2017-05-16 09:53 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
        2017-05-16 09:53 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
        2017-05-16 09:53 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
        2017-05-16 09:53 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
        2017-05-16 09:53 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
        2017-05-16 09:53 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
        2017-05-16 09:53 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
        2017-05-16 09:53 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
        2017-05-16 09:53 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
        2017-05-16 09:53 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
        2017-05-16 09:53 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
        2017-05-16 09:53 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
        2017-05-16 09:53 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
        2017-05-16 09:52 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
        2017-05-16 09:52 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
        2017-05-16 09:52 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
        2017-05-16 09:52 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
        2017-05-16 09:52 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
        2017-05-16 09:52 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
        2017-05-16 09:52 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
        2017-05-16 09:52 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
        2017-05-16 09:52 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
        2017-05-16 09:52 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
        2017-05-16 09:52 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
        2017-05-16 09:52 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
        2017-05-16 09:52 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
        2017-05-16 09:52 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
        2017-05-16 09:52 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
        2017-05-16 09:52 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
        2017-05-16 09:52 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
        2017-05-16 09:52 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
        2017-05-16 09:52 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
        2017-05-16 09:52 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
        2017-05-16 09:52 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
        2017-05-16 09:52 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
        2017-05-16 09:52 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
        2017-05-16 09:52 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
        2017-05-16 09:52 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
        2017-05-16 09:52 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
        2017-05-16 09:52 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
        2017-05-16 09:52 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
        2017-05-16 09:52 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
        2017-05-16 09:52 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
        2017-05-16 09:52 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
        2017-05-16 09:52 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
        2017-05-16 09:52 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
        2017-05-16 09:52 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
        2017-05-16 09:52 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
        2017-05-16 09:52 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
        2017-05-16 09:52 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
        2017-05-16 09:52 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
        2017-05-16 09:52 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
        2017-05-16 09:52 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
        2017-05-16 09:52 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
        2017-05-16 09:52 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
        2017-05-16 09:52 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
        2017-05-16 09:52 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
        2017-05-16 09:52 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
        2017-05-16 09:52 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
        2017-05-16 09:52 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
        2017-05-16 09:52 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
        2017-05-16 09:52 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
        2017-05-16 09:52 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
        2017-05-16 09:52 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
        2017-05-16 09:52 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
        2017-05-16 09:52 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
        2017-05-16 09:52 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
        2017-05-16 09:52 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
        2017-05-16 09:52 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
        2017-05-16 09:52 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
        2017-05-16 09:52 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
        2017-05-16 09:52 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
        2017-05-16 09:52 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
        2017-05-16 09:52 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
        2017-05-16 09:52 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
        2017-05-16 09:52 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
        2017-05-16 09:52 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
        2017-05-16 09:52 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
        2017-05-16 09:52 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
        2017-05-16 09:52 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
        2017-05-16 09:50 - 2017-05-16 09:53 - 00000000 ____D C:\Windows\SysWOW64\directx
        2017-05-16 09:50 - 2017-05-16 09:50 - 00292184 _____ (Microsoft Corporation) C:\Users\Vesi\Downloads\dxwebsetup.exe
        2017-05-16 09:46 - 2015-06-07 02:13 - 00961192 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00062304 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:13 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00883712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00064352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
        2017-05-16 09:46 - 2015-06-07 02:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
        2017-05-16 09:37 - 2017-05-16 09:37 - 00000780 _____ C:\Users\Vesi\Desktop\Start CSGO No Internet.lnk
        2017-05-16 09:37 - 2017-05-16 09:37 - 00000777 _____ C:\Users\Vesi\Desktop\Counter-Strike Global Offensive.lnk
        2017-05-16 09:37 - 2017-05-16 09:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike Global Offensive
        2017-05-16 08:43 - 2017-05-16 08:43 - 00014199 _____ C:\Users\Vesi\Downloads\Counter-Strike Global Offensive v1.35.6.3 [Repack].torrent
        2017-05-16 08:40 - 2017-05-16 09:01 - 00000000 ____D C:\Users\Vesi\Downloads\CSGO v1.35.6.3
        2017-05-08 23:31 - 2017-05-08 23:31 - 00760687 _____ C:\Users\Vesi\Downloads\6C3A.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00505546 _____ C:\Users\Vesi\Downloads\6804.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00343456 _____ C:\Users\Vesi\Downloads\6A7F.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00305314 _____ C:\Users\Vesi\Downloads\5676.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00289788 _____ C:\Users\Vesi\Downloads\57E2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00282232 _____ C:\Users\Vesi\Downloads\69E0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00251518 _____ C:\Users\Vesi\Downloads\8C85.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00240803 _____ C:\Users\Vesi\Downloads\7B36.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00213208 _____ C:\Users\Vesi\Downloads\7FF3.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00209280 _____ C:\Users\Vesi\Downloads\541C.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00191484 _____ C:\Users\Vesi\Downloads\6950.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00172989 _____ C:\Users\Vesi\Downloads\7F83.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00157981 _____ C:\Users\Vesi\Downloads\6CA9.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00152853 _____ C:\Users\Vesi\Downloads\70A4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00148283 _____ C:\Users\Vesi\Downloads\5881.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00148123 _____ C:\Users\Vesi\Downloads\69A0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00139041 _____ C:\Users\Vesi\Downloads\56B5.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00132319 _____ C:\Users\Vesi\Downloads\5BA2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00131544 _____ C:\Users\Vesi\Downloads\55A7.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00129077 _____ C:\Users\Vesi\Downloads\79EA.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00114513 _____ C:\Users\Vesi\Downloads\7FD3.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00113458 _____ C:\Users\Vesi\Downloads\70E3.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00112059 _____ C:\Users\Vesi\Downloads\75A2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00107143 _____ C:\Users\Vesi\Downloads\7113.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00106055 _____ C:\Users\Vesi\Downloads\8023.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00104816 _____ C:\Users\Vesi\Downloads\5753.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00103366 _____ C:\Users\Vesi\Downloads\68D1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00101136 _____ C:\Users\Vesi\Downloads\A710.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00097330 _____ C:\Users\Vesi\Downloads\629E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00094880 _____ C:\Users\Vesi\Downloads\5714.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00092382 _____ C:\Users\Vesi\Downloads\60CF.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00091478 _____ C:\Users\Vesi\Downloads\643F.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00090226 _____ C:\Users\Vesi\Downloads\54BA.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00087561 _____ C:\Users\Vesi\Downloads\799A.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00087080 _____ C:\Users\Vesi\Downloads\8183.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00084455 _____ C:\Users\Vesi\Downloads\5548.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00082714 _____ C:\Users\Vesi\Downloads\7AA9.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00077441 _____ C:\Users\Vesi\Downloads\7D3E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00075364 _____ C:\Users\Vesi\Downloads\5831.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00074703 _____ C:\Users\Vesi\Downloads\5BF2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00074629 _____ C:\Users\Vesi\Downloads\6E36.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00070208 _____ C:\Users\Vesi\Downloads\6ED5.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00068647 _____ C:\Users\Vesi\Downloads\630E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00066235 _____ C:\Users\Vesi\Downloads\7074.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00063956 _____ C:\Users\Vesi\Downloads\52DE.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00062855 _____ C:\Users\Vesi\Downloads\59A1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00061942 _____ C:\Users\Vesi\Downloads\65F9.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00060402 _____ C:\Users\Vesi\Downloads\67A4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00059159 _____ C:\Users\Vesi\Downloads\5152.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00057911 _____ C:\Users\Vesi\Downloads\55F6.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00057211 _____ C:\Users\Vesi\Downloads\5220.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00056910 _____ C:\Users\Vesi\Downloads\8521.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00056541 _____ C:\Users\Vesi\Downloads\62CE.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00055417 _____ C:\Users\Vesi\Downloads\59C1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00055097 _____ C:\Users\Vesi\Downloads\8D33.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00054443 _____ C:\Users\Vesi\Downloads\641F.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00053889 _____ C:\Users\Vesi\Downloads\53EC.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00052152 _____ C:\Users\Vesi\Downloads\5F93.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00051415 _____ C:\Users\Vesi\Downloads\6B9B.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00051008 _____ C:\Users\Vesi\Downloads\526F.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00050616 _____ C:\Users\Vesi\Downloads\7532.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00049777 _____ C:\Users\Vesi\Downloads\8B26.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00049622 _____ C:\Users\Vesi\Downloads\7730.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00048842 _____ C:\Users\Vesi\Downloads\5792.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00048566 _____ C:\Users\Vesi\Downloads\6BFB.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00048496 _____ C:\Users\Vesi\Downloads\58D1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00048163 _____ C:\Users\Vesi\Downloads\67D4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00048104 _____ C:\Users\Vesi\Downloads\7242.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00047398 _____ C:\Users\Vesi\Downloads\7C03.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00045770 _____ C:\Users\Vesi\Downloads\5A83.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00045717 _____ C:\Users\Vesi\Downloads\6D97.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00045646 _____ C:\Users\Vesi\Downloads\5A62.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00043929 _____ C:\Users\Vesi\Downloads\7FA3.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00043283 _____ C:\Users\Vesi\Downloads\51D1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00043187 _____ C:\Users\Vesi\Downloads\5B01.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00043049 _____ C:\Users\Vesi\Downloads\50C4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00040358 _____ C:\Users\Vesi\Downloads\5A22.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00039738 _____ C:\Users\Vesi\Downloads\68B1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00039533 _____ C:\Users\Vesi\Downloads\5085.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00039400 _____ C:\Users\Vesi\Downloads\6872.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00037779 _____ C:\Users\Vesi\Downloads\57C2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00037060 _____ C:\Users\Vesi\Downloads\8FC0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00036569 _____ C:\Users\Vesi\Downloads\59E2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00035503 _____ C:\Users\Vesi\Downloads\7392.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00035375 _____ C:\Users\Vesi\Downloads\82C4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00034978 _____ C:\Users\Vesi\Downloads\529E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00034533 _____ C:\Users\Vesi\Downloads\6970.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00033779 _____ C:\Users\Vesi\Downloads\5DCC.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00033173 _____ C:\Users\Vesi\Downloads\5B22.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00032991 _____ C:\Users\Vesi\Downloads\5646.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00032751 _____ C:\Users\Vesi\Downloads\546B.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00032725 _____ C:\Users\Vesi\Downloads\76A2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00032033 _____ C:\Users\Vesi\Downloads\5BD2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00031993 _____ C:\Users\Vesi\Downloads\7CB0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00031961 _____ C:\Users\Vesi\Downloads\63FF.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00031487 _____ C:\Users\Vesi\Downloads\8163.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00031063 _____ C:\Users\Vesi\Downloads\634E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00030732 _____ C:\Users\Vesi\Downloads\639E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00030372 _____ C:\Users\Vesi\Downloads\5852.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00029953 _____ C:\Users\Vesi\Downloads\797A.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00028868 _____ C:\Users\Vesi\Downloads\5B62.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00028805 _____ C:\Users\Vesi\Downloads\7582.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00027813 _____ C:\Users\Vesi\Downloads\71A3.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00027749 _____ C:\Users\Vesi\Downloads\618F.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00027379 _____ C:\Users\Vesi\Downloads\5C82.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00027076 _____ C:\Users\Vesi\Downloads\6A2F.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00026975 _____ C:\Users\Vesi\Downloads\5CA2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00026957 _____ C:\Users\Vesi\Downloads\614F.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00026947 _____ C:\Users\Vesi\Downloads\73B2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00026269 _____ C:\Users\Vesi\Downloads\7153.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00025301 _____ C:\Users\Vesi\Downloads\616F.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00023565 _____ C:\Users\Vesi\Downloads\73D3.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00023129 _____ C:\Users\Vesi\Downloads\6080.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00023045 _____ C:\Users\Vesi\Downloads\624E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00022508 _____ C:\Users\Vesi\Downloads\5FF2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00022274 _____ C:\Users\Vesi\Downloads\72B2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00021896 _____ C:\Users\Vesi\Downloads\8C56.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00021890 _____ C:\Users\Vesi\Downloads\7322.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00021856 _____ C:\Users\Vesi\Downloads\7212.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00021805 _____ C:\Users\Vesi\Downloads\66A8.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00021740 _____ C:\Users\Vesi\Downloads\6F04.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00021147 _____ C:\Users\Vesi\Downloads\7483.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00019964 _____ C:\Users\Vesi\Downloads\61D0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00019832 _____ C:\Users\Vesi\Downloads\781E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00019814 _____ C:\Users\Vesi\Downloads\5EE6.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00019760 _____ C:\Users\Vesi\Downloads\8415.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00019559 _____ C:\Users\Vesi\Downloads\5B92.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00018653 _____ C:\Users\Vesi\Downloads\54F9.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00018406 _____ C:\Users\Vesi\Downloads\5AB2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00018336 _____ C:\Users\Vesi\Downloads\74A3.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00017959 _____ C:\Users\Vesi\Downloads\5C42.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00017709 _____ C:\Users\Vesi\Downloads\80A4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00017413 _____ C:\Users\Vesi\Downloads\5191.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00017222 _____ C:\Users\Vesi\Downloads\8464.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00017011 _____ C:\Users\Vesi\Downloads\64DE.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00016587 _____ C:\Users\Vesi\Downloads\8E71.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00016578 _____ C:\Users\Vesi\Downloads\7F05.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00016312 _____ C:\Users\Vesi\Downloads\5B42.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00016253 _____ C:\Users\Vesi\Downloads\7173.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00016180 _____ C:\Users\Vesi\Downloads\8294.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00016134 _____ C:\Users\Vesi\Downloads\612F.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00016131 _____ C:\Users\Vesi\Downloads\63DE.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00016129 _____ C:\Users\Vesi\Downloads\63BE.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00015991 _____ C:\Users\Vesi\Downloads\7E49.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00015833 _____ C:\Users\Vesi\Downloads\7B85.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00015506 _____ C:\Users\Vesi\Downloads\7A39.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00015290 _____ C:\Users\Vesi\Downloads\6E75.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00015176 _____ C:\Users\Vesi\Downloads\6BCB.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00015047 _____ C:\Users\Vesi\Downloads\7D9C.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00014765 _____ C:\Users\Vesi\Downloads\6060.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00014385 _____ C:\Users\Vesi\Downloads\8254.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00014129 _____ C:\Users\Vesi\Downloads\636E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00014080 _____ C:\Users\Vesi\Downloads\81A3.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00013723 _____ C:\Users\Vesi\Downloads\8102.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00013318 _____ C:\Users\Vesi\Downloads\8364.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00013148 _____ C:\Users\Vesi\Downloads\532D.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00012673 _____ C:\Users\Vesi\Downloads\7A79.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00012646 _____ C:\Users\Vesi\Downloads\73F3.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00012518 _____ C:\Users\Vesi\Downloads\5921.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00012453 _____ C:\Users\Vesi\Downloads\71E2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00012215 _____ C:\Users\Vesi\Downloads\6774.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00012045 _____ C:\Users\Vesi\Downloads\7562.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00011776 _____ C:\Users\Vesi\Downloads\7342.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00011634 _____ C:\Users\Vesi\Downloads\5A02.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00011329 _____ C:\Users\Vesi\Downloads\53AD.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00011225 _____ C:\Users\Vesi\Downloads\7C61.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00010672 _____ C:\Users\Vesi\Downloads\8274.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00010216 _____ C:\Users\Vesi\Downloads\78EB.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00009449 _____ C:\Users\Vesi\Downloads\6E06.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00009125 _____ C:\Users\Vesi\Downloads\632E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00009050 _____ C:\Users\Vesi\Downloads\58F2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00008905 _____ C:\Users\Vesi\Downloads\7612.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00008541 _____ C:\Users\Vesi\Downloads\792A.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00008323 _____ C:\Users\Vesi\Downloads\901F.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00008144 _____ C:\Users\Vesi\Downloads\8143.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00008086 _____ C:\Users\Vesi\Downloads\76E1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00007987 _____ C:\Users\Vesi\Downloads\5942.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00007963 _____ C:\Users\Vesi\Downloads\6F64.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00007929 _____ C:\Users\Vesi\Downloads\6F34.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00007764 _____ C:\Users\Vesi\Downloads\8F70.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00007738 _____ C:\Users\Vesi\Downloads\647E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00007732 _____ C:\Users\Vesi\Downloads\8EB0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00007652 _____ C:\Users\Vesi\Downloads\5962.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00007557 _____ C:\Users\Vesi\Downloads\84E2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00007438 _____ C:\Users\Vesi\Downloads\907E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00007222 _____ C:\Users\Vesi\Downloads\6DC6.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00007203 _____ C:\Users\Vesi\Downloads\8F90.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00007178 _____ C:\Users\Vesi\Downloads\5626.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00006999 _____ C:\Users\Vesi\Downloads\8FEF.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00006691 _____ C:\Users\Vesi\Downloads\6ADD.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00006509 _____ C:\Users\Vesi\Downloads\6619.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00006297 _____ C:\Users\Vesi\Downloads\8204.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00006095 _____ C:\Users\Vesi\Downloads\90FC.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00006036 _____ C:\Users\Vesi\Downloads\8B95.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00005934 _____ C:\Users\Vesi\Downloads\75F2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00005738 _____ C:\Users\Vesi\Downloads\6FB4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00005437 _____ C:\Users\Vesi\Downloads\7642.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00005244 _____ C:\Users\Vesi\Downloads\8F40.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00005222 _____ C:\Users\Vesi\Downloads\6901.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00005217 _____ C:\Users\Vesi\Downloads\7443.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00005114 _____ C:\Users\Vesi\Downloads\627E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00005097 _____ C:\Users\Vesi\Downloads\77ED.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00005045 _____ C:\Users\Vesi\Downloads\621F.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00005030 _____ C:\Users\Vesi\Downloads\6B2C.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00004882 _____ C:\Users\Vesi\Downloads\6A5E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00004675 _____ C:\Users\Vesi\Downloads\7662.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00004673 _____ C:\Users\Vesi\Downloads\72D2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00004460 _____ C:\Users\Vesi\Downloads\81E4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00004459 _____ C:\Users\Vesi\Downloads\8EE0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00004435 _____ C:\Users\Vesi\Downloads\92B4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00004415 _____ C:\Users\Vesi\Downloads\9189.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00004257 _____ C:\Users\Vesi\Downloads\9275.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003972 _____ C:\Users\Vesi\Downloads\9304.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003921 _____ C:\Users\Vesi\Downloads\83C4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003918 _____ C:\Users\Vesi\Downloads\8394.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003892 _____ C:\Users\Vesi\Downloads\6EA5.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003891 _____ C:\Users\Vesi\Downloads\6679.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003882 _____ C:\Users\Vesi\Downloads\92E4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003849 _____ C:\Users\Vesi\Downloads\9394.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003810 _____ C:\Users\Vesi\Downloads\7372.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003727 _____ C:\Users\Vesi\Downloads\8F00.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003725 _____ C:\Users\Vesi\Downloads\7463.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003655 _____ C:\Users\Vesi\Downloads\81C4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003616 _____ C:\Users\Vesi\Downloads\8063.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003601 _____ C:\Users\Vesi\Downloads\9364.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003524 _____ C:\Users\Vesi\Downloads\535D.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003510 _____ C:\Users\Vesi\Downloads\93C4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003411 _____ C:\Users\Vesi\Downloads\91F7.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003375 _____ C:\Users\Vesi\Downloads\5C22.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003364 _____ C:\Users\Vesi\Downloads\9334.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003208 _____ C:\Users\Vesi\Downloads\8334.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003190 _____ C:\Users\Vesi\Downloads\7423.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00003124 _____ C:\Users\Vesi\Downloads\8084.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00002913 _____ C:\Users\Vesi\Downloads\64AE.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00002875 _____ C:\Users\Vesi\Downloads\8DF2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00002850 _____ C:\Users\Vesi\Downloads\7024.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00002793 _____ C:\Users\Vesi\Downloads\89D7.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00002789 _____ C:\Users\Vesi\Downloads\82E4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00002649 _____ C:\Users\Vesi\Downloads\58B1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00002631 _____ C:\Users\Vesi\Downloads\61BF.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00002308 _____ C:\Users\Vesi\Downloads\779E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00002251 _____ C:\Users\Vesi\Downloads\5CC2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00002129 _____ C:\Users\Vesi\Downloads\8AD5.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00002000 _____ C:\Users\Vesi\Downloads\85FF.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001971 _____ C:\Users\Vesi\Downloads\8123.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001900 _____ C:\Users\Vesi\Downloads\8BE5.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001839 _____ C:\Users\Vesi\Downloads\88A8.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001827 _____ C:\Users\Vesi\Downloads\8234.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001824 _____ C:\Users\Vesi\Downloads\8987.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001797 _____ C:\Users\Vesi\Downloads\65B9.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001795 _____ C:\Users\Vesi\Downloads\876D.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001769 _____ C:\Users\Vesi\Downloads\A750.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001727 _____ C:\Users\Vesi\Downloads\8859.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001721 _____ C:\Users\Vesi\Downloads\8A06.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001714 _____ C:\Users\Vesi\Downloads\8BB6.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001685 _____ C:\Users\Vesi\Downloads\8907.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001671 _____ C:\Users\Vesi\Downloads\85A1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001670 _____ C:\Users\Vesi\Downloads\7262.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001635 _____ C:\Users\Vesi\Downloads\89A7.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001597 _____ C:\Users\Vesi\Downloads\8314.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001589 _____ C:\Users\Vesi\Downloads\87BC.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001537 _____ C:\Users\Vesi\Downloads\5A42.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001487 _____ C:\Users\Vesi\Downloads\86BD.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001445 _____ C:\Users\Vesi\Downloads\872D.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001434 _____ C:\Users\Vesi\Downloads\8A27.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001428 _____ C:\Users\Vesi\Downloads\8A56.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001414 _____ C:\Users\Vesi\Downloads\8B66.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001389 _____ C:\Users\Vesi\Downloads\7282.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001380 _____ C:\Users\Vesi\Downloads\794A.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001358 _____ C:\Users\Vesi\Downloads\8C15.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001323 _____ C:\Users\Vesi\Downloads\86FD.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001253 _____ C:\Users\Vesi\Downloads\9AAC.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001241 _____ C:\Users\Vesi\Downloads\8E22.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001238 _____ C:\Users\Vesi\Downloads\9630.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001226 _____ C:\Users\Vesi\Downloads\9C9C.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001221 _____ C:\Users\Vesi\Downloads\9A1D.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001219 _____ C:\Users\Vesi\Downloads\9B4C.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001218 _____ C:\Users\Vesi\Downloads\9581.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001210 _____ C:\Users\Vesi\Downloads\9E84.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001208 _____ C:\Users\Vesi\Downloads\A3EC.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001207 _____ C:\Users\Vesi\Downloads\A211.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001204 _____ C:\Users\Vesi\Downloads\A141.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001199 _____ C:\Users\Vesi\Downloads\9BDD.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001198 _____ C:\Users\Vesi\Downloads\9801.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001196 _____ C:\Users\Vesi\Downloads\98B2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001189 _____ C:\Users\Vesi\Downloads\9721.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001187 _____ C:\Users\Vesi\Downloads\9542.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001185 _____ C:\Users\Vesi\Downloads\A2C0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001183 _____ C:\Users\Vesi\Downloads\A4D8.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001179 _____ C:\Users\Vesi\Downloads\9610.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001178 _____ C:\Users\Vesi\Downloads\A469.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001177 _____ C:\Users\Vesi\Downloads\96E1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001174 _____ C:\Users\Vesi\Downloads\A071.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001173 _____ C:\Users\Vesi\Downloads\A0B1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001173 _____ C:\Users\Vesi\Downloads\9650.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001165 _____ C:\Users\Vesi\Downloads\9B6C.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001164 _____ C:\Users\Vesi\Downloads\A2A0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001159 _____ C:\Users\Vesi\Downloads\8AA5.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001157 _____ C:\Users\Vesi\Downloads\A231.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001156 _____ C:\Users\Vesi\Downloads\9872.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001154 _____ C:\Users\Vesi\Downloads\A37D.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001154 _____ C:\Users\Vesi\Downloads\A200.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001154 _____ C:\Users\Vesi\Downloads\9E64.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001151 _____ C:\Users\Vesi\Downloads\9B8D.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001149 _____ C:\Users\Vesi\Downloads\9701.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001148 _____ C:\Users\Vesi\Downloads\9BBC.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001148 _____ C:\Users\Vesi\Downloads\9751.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001147 _____ C:\Users\Vesi\Downloads\A0E1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001144 _____ C:\Users\Vesi\Downloads\97D2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001141 _____ C:\Users\Vesi\Downloads\A190.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001140 _____ C:\Users\Vesi\Downloads\95D0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001139 _____ C:\Users\Vesi\Downloads\9D69.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001139 _____ C:\Users\Vesi\Downloads\98E2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001137 _____ C:\Users\Vesi\Downloads\8D72.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001137 _____ C:\Users\Vesi\Downloads\8D03.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001135 _____ C:\Users\Vesi\Downloads\9771.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001133 _____ C:\Users\Vesi\Downloads\A000.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001132 _____ C:\Users\Vesi\Downloads\999F.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001131 _____ C:\Users\Vesi\Downloads\A021.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001129 _____ C:\Users\Vesi\Downloads\A5F2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001129 _____ C:\Users\Vesi\Downloads\A010.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001127 _____ C:\Users\Vesi\Downloads\9FE0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001127 _____ C:\Users\Vesi\Downloads\9B1C.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001125 _____ C:\Users\Vesi\Downloads\9AFC.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001116 _____ C:\Users\Vesi\Downloads\A111.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001115 _____ C:\Users\Vesi\Downloads\A517.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001115 _____ C:\Users\Vesi\Downloads\9892.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001115 _____ C:\Users\Vesi\Downloads\9842.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001112 _____ C:\Users\Vesi\Downloads\9C0C.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001112 _____ C:\Users\Vesi\Downloads\9A6C.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001111 _____ C:\Users\Vesi\Downloads\A6A2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001110 _____ C:\Users\Vesi\Downloads\9A8C.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001110 _____ C:\Users\Vesi\Downloads\9791.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001102 _____ C:\Users\Vesi\Downloads\A652.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001100 _____ C:\Users\Vesi\Downloads\9C2D.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001100 _____ C:\Users\Vesi\Downloads\9822.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001100 _____ C:\Users\Vesi\Downloads\96C0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001095 _____ C:\Users\Vesi\Downloads\9E44.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001093 _____ C:\Users\Vesi\Downloads\97B1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001090 _____ C:\Users\Vesi\Downloads\9691.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001087 _____ C:\Users\Vesi\Downloads\9EA5.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001086 _____ C:\Users\Vesi\Downloads\9FA0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001085 _____ C:\Users\Vesi\Downloads\A091.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001083 _____ C:\Users\Vesi\Downloads\A041.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001081 _____ C:\Users\Vesi\Downloads\9ACC.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001067 _____ C:\Users\Vesi\Downloads\9D1A.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001064 _____ C:\Users\Vesi\Downloads\8DC2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001063 _____ C:\Users\Vesi\Downloads\A622.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001061 _____ C:\Users\Vesi\Downloads\9522.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001052 _____ C:\Users\Vesi\Downloads\75E1.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001048 _____ C:\Users\Vesi\Downloads\A1D0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001042 _____ C:\Users\Vesi\Downloads\A672.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001040 _____ C:\Users\Vesi\Downloads\94F2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001037 _____ C:\Users\Vesi\Downloads\9F13.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001018 _____ C:\Users\Vesi\Downloads\9931.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001018 _____ C:\Users\Vesi\Downloads\9670.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00001009 _____ C:\Users\Vesi\Downloads\A251.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000992 _____ C:\Users\Vesi\Downloads\6D67.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000991 _____ C:\Users\Vesi\Downloads\6D17.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000979 _____ C:\Users\Vesi\Downloads\8571.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000976 _____ C:\Users\Vesi\Downloads\9433.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000970 _____ C:\Users\Vesi\Downloads\A1B0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000925 _____ C:\Users\Vesi\Downloads\8937.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000880 _____ C:\Users\Vesi\Downloads\8D93.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000862 _____ C:\Users\Vesi\Downloads\9C5C.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000860 _____ C:\Users\Vesi\Downloads\A2F0.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000858 _____ C:\Users\Vesi\Downloads\6F84.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000783 _____ C:\Users\Vesi\Downloads\86DD.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000768 _____ C:\Users\Vesi\Downloads\866E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000726 _____ C:\Users\Vesi\Downloads\6649.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000702 _____ C:\Users\Vesi\Downloads\6D47.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000682 _____ C:\Users\Vesi\Downloads\538C.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000614 _____ C:\Users\Vesi\Downloads\7512.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000574 _____ C:\Users\Vesi\Downloads\7004.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000529 _____ C:\Users\Vesi\Downloads\874D.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000522 _____ C:\Users\Vesi\Downloads\8B16.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000500 _____ C:\Users\Vesi\Downloads\8053.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000489 _____ C:\Users\Vesi\Downloads\610E.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000487 _____ C:\Users\Vesi\Downloads\94D2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000458 _____ C:\Users\Vesi\Downloads\93F3.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000416 _____ C:\Users\Vesi\Downloads\6B6C.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000342 _____ C:\Users\Vesi\Downloads\8966.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000308 _____ C:\Users\Vesi\Downloads\7054.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000270 _____ C:\Users\Vesi\Downloads\94A2.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000267 _____ C:\Users\Vesi\Downloads\8AF5.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000260 _____ C:\Users\Vesi\Downloads\7302.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000240 _____ C:\Users\Vesi\Downloads\6FE4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000235 _____ C:\Users\Vesi\Downloads\9472.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000219 _____ C:\Users\Vesi\Downloads\8404.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000187 _____ C:\Users\Vesi\Downloads\8560.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000183 _____ C:\Users\Vesi\Downloads\83E4.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000095 _____ C:\Users\Vesi\Downloads\78AB.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000043 _____ C:\Users\Vesi\Downloads\8C45.tmp
        2017-05-08 23:31 - 2017-05-08 23:31 - 00000000 _____ C:\Users\Vesi\Downloads\A78F.tmp
        2017-05-06 22:47 - 2017-05-06 22:49 - 00000000 ____D C:\Users\Vesi\Downloads\Training.Day.2001.DC.BDRip.XviD.AC3.BGAUDiO-HS0
        2017-05-02 22:56 - 2017-05-02 22:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
        2017-05-02 22:55 - 2017-05-02 22:55 - 00000000 ____D C:\ProgramData\McAfee Security Scan
        2017-04-18 22:27 - 2017-04-18 22:27 - 00003162 _____ C:\Windows\System32\Tasks\{3828B88B-74ED-42B5-A0FB-1CB52D9143A8}
        2017-04-18 22:24 - 2017-04-18 22:26 - 00000000 ____D C:\Users\Vesi\AppData\Roaming\discord
        2017-04-18 22:24 - 2017-04-18 22:24 - 00002154 _____ C:\Users\Vesi\Desktop\Discord.lnk
        2017-04-18 22:24 - 2017-04-18 22:24 - 00000000 ____D C:\Users\Vesi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc
        2017-04-18 22:24 - 2017-04-18 22:24 - 00000000 ____D C:\Users\Vesi\AppData\Local\SquirrelTemp
        2017-04-18 22:24 - 2017-04-18 22:24 - 00000000 ____D C:\Users\Vesi\AppData\Local\Discord
        2017-04-18 22:22 - 2017-04-18 22:23 - 52553728 _____ (Hammer & Chisel, Inc.) C:\Users\Vesi\Downloads\DiscordSetup.exe
        2017-04-18 22:20 - 2017-04-18 22:20 - 00000000 ____D C:\3a2771e5ad8a12e64c5c7a
        2017-04-18 22:18 - 2017-04-18 22:19 - 01631704 _____ (Skype Technologies S.A.) C:\Users\Vesi\Downloads\SkypeSetup (1).exe
        2017-04-18 22:18 - 2017-04-18 22:18 - 01631704 _____ (Skype Technologies S.A.) C:\Users\Vesi\Downloads\SkypeSetup.exe
        ==================== One Month Modified files and folders ========
        (If an entry is included in the fixlist, the file/folder will be moved.)
        2017-05-16 14:23 - 2015-01-04 12:25 - 00000000 ____D C:\Users\Vesi\AppData\Roaming\uTorrent
        2017-05-16 14:03 - 2015-01-04 16:42 - 00002405 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
        2017-05-16 14:03 - 2015-01-04 16:42 - 00002393 _____ C:\Users\Public\Desktop\Google Chrome.lnk
        2017-05-16 13:55 - 2015-01-08 13:41 - 00000000 ____D C:\ProgramData\Malwarebytes
        2017-05-16 11:22 - 2009-07-14 07:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
        2017-05-16 11:22 - 2009-07-14 07:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
        2017-05-16 11:19 - 2009-07-14 08:13 - 00781790 _____ C:\Windows\system32\PerfStringBackup.INI
        2017-05-16 11:19 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\inf
        2017-05-16 11:14 - 2009-07-14 08:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
        2017-05-16 09:50 - 2015-01-03 14:37 - 00000000 ____D C:\temp
        2017-05-16 09:46 - 2015-01-03 14:07 - 00000000 ____D C:\ProgramData\Package Cache
        2017-05-07 05:25 - 2015-04-16 15:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
        2017-05-06 13:52 - 2015-01-13 10:07 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
        2017-05-02 22:56 - 2017-02-09 23:48 - 00001964 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
        2017-05-02 22:56 - 2015-11-13 22:23 - 00000000 ____D C:\Program Files\McAfee Security Scan
        2017-05-02 22:56 - 2015-01-04 16:41 - 00003430 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
        2017-05-02 22:56 - 2015-01-04 16:41 - 00003302 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
        Some files in TEMP:
        ====================
        2016-10-10 16:02 - 2016-10-10 16:03 - 37642072 _____ (PandoraTV) C:\Users\Vesi\AppData\Local\Temp\KMP_4.1.3.3.exe
        2016-10-10 16:05 - 2016-10-10 16:04 - 3971208 _____ (Ask) C:\Users\Vesi\AppData\Local\Temp\setup.exe
        2016-06-24 00:21 - 2016-06-24 00:21 - 2133504 _____ (BitTorrent Inc.) C:\Users\Vesi\AppData\Local\Temp\utt4E1F.tmp.exe
        2017-04-18 22:19 - 2017-04-18 22:19 - 14456872 _____ (Microsoft Corporation) C:\Users\Vesi\AppData\Local\Temp\vc_redist.x86.exe
        ==================== Bamital & volsnap ======================
        (There is no automatic fix for files that do not pass verification.)
        C:\Windows\system32\winlogon.exe => File is digitally signed
        C:\Windows\system32\wininit.exe => File is digitally signed
        C:\Windows\SysWOW64\wininit.exe => File is digitally signed
        C:\Windows\explorer.exe => File is digitally signed
        C:\Windows\SysWOW64\explorer.exe => File is digitally signed
        C:\Windows\system32\svchost.exe => File is digitally signed
        C:\Windows\SysWOW64\svchost.exe => File is digitally signed
        C:\Windows\system32\services.exe => File is digitally signed
        C:\Windows\system32\User32.dll => File is digitally signed
        C:\Windows\SysWOW64\User32.dll => File is digitally signed
        C:\Windows\system32\userinit.exe => File is digitally signed
        C:\Windows\SysWOW64\userinit.exe => File is digitally signed
        C:\Windows\system32\rpcss.dll => File is digitally signed
        C:\Windows\system32\dnsapi.dll => File is digitally signed
        C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
        C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
        LastRegBack: 2017-05-14 22:40
        ==================== End of FRST.txt ============================
      • от izipop
        Компютъра се натовари при инсталация на нещо .... промени се началната страница на Google. Пуснах Malwarebytes - откри 7 обекта, два от които Hijack. 
      • от petyaf
        Здравейте, имам нужда от помощ! Теглих заразен крак с вируси и инсталирах програми с йероглифи. Една от тях беше Yea Desktop. След това сканирах с Malwarebytes и тя откри над 1500 заплахи. Сканирах и с други програми, но струва ми се нещата не изглеждат добре. Ето резултата:
        Addition 2.txt
      • от stoy@n
        Здавейте,
        Сканирах с Malwarebytes, но не откри нищо. Зарежда много бавно и с хром и с интернет експлорър. Също така отваря бавно и файлове от компютъра. Температурата на процесора не се покачва над 39-40 градуса по целзий. Процесора за кратко се натоварва до 70-80 % и после спада до 4-5%.Не намирам причина в хардуера, а в същото време и от сканирането не показва да има проблем с вируси. Прилагам прикачени логовете от FRST, от последното сканиране с MBAM и  скрииншот за модела и операционната система.  
        Поздрави,
        Стоян
        Addition.txt
        FRST.txt
        Mbam history log.txt
        Mbam Protection log.txt

      • от b2188905
        Здравейте,
         
        При мен пристигна стар компютър с оплакването че "унищожава флашки". Бърз поглед на една "унищожена" флашка показа че файловете се преместени в скрита директория а на в корена е поставена шорткът който стартира скрито dll – подозирам симулира отваряне на фолдер и едновременно с това върши други безобразия - вирустотал на това dll там
        На компютъра имаше инсталиран някакъв нортон (!), отдавна не работещ, който деинсталирах. Докарах "Avira PC Cleaner", който откри още няколко пъти същата зараза плюс файл "syshost.exe" в директорията c:\WINDOWS\Installer\{4A3D9C42-B6F9-83E6-FFED-5B77DFD83413} и изтри всичко с изключение на този последния файл. Ребоот не помогна, процес свързан с този файл не съществува, не се открива като "handle" от processhacker.
        Успях да преместя директорията, но файла не мога да изтрия и не мога да преименувам, въпреки че съм администратор. Вирустотал на този файл там. Въпреки че в репорта се споменава локи не съм забелязал криптирани файлове.
        Syshost.exe се споменаваше в регистрито на няколко места като сървис, а ключовете бяха "защитени" от изтриване. Изтрих ги след като промених пермишъните.
         
        Как да изтрия заключения файл и да довърша почистването?
         
        Забелязах че boot.ini също заключен. Не мога да го преместя, редактирам или променя атрибутите.
        Закачам файловете от FRST.
         
        Нямам физически достъп до компютъра, така че подходът "пускане на линукс и екстерминиране на гадовете" е практически невъзможен. Стигам до него чрез "UltraVNC SC". Процесите winvnc.exe и ArmenskiPopHelpDesk.exe са от него.
         
        Компютърът е ползван само за пишеща машина. Никога не е ползван за "интернет" (наистина, интернет експлорер не беше пускан, а фирефокса го инсталирах аз), но изгледжа ъпдейтнат до дупка.
         
        Благодаря
        ь ф - Addition.txt
        ь ф - FRST.txt
    • Разглеждащи в момента   0 потребители

      Няма регистрирани потребители разглеждащи тази страница.

    • Дарение